GitHub Advisory Database
Security vulnerability database inclusive of CVEs and GitHub originated security advisories from the world of open source software.
Filter advisories
GitHub reviewed advisories
Unreviewed advisories
Malware advisories
Filter advisories
Filter advisories
GitHub reviewed advisories
All reviewed
5,000+
Composer
5,000+
Erlang
116
GitHub Actions
55
Go
4,701
Maven
5,000+
npm
5,000+
NuGet
1,104
pip
5,000+
Pub
13
RubyGems
1,150
Rust
1,566
Swift
62
Unreviewed advisories
All unreviewed
5,000+
Malware advisories
All malware
5,000+
Composer
2
Go
18
Maven
2
npm
5,000+
NuGet
264
pip
5,000+
RubyGems
3,510
Rust
19
599 advisories
Filter by severity
Craft CMS: Authenticated leak of secret environment variables
Moderate
CVE-2026-72782
was published
for
craftcms/cms
(Composer)
Aug 6, 2026
SiYuan 3.8.0 contains a path traversal / sensitive file exposure vulnerability in the...
Moderate
Unreviewed
CVE-2026-82650
was published
Aug 30, 2026
SiYuan before v3.8.1 fails to filter invisible-tier content from SQL embed blocks, attribute-view...
Moderate
Unreviewed
CVE-2026-82652
was published
Aug 30, 2026
Improper resource exposure in StreamsAPI in Google Chrome prior to 152.0.7977.65 allowed a remote...
Moderate
Unreviewed
CVE-2026-79068
was published
Aug 25, 2026
In Spring AI's Semantic Cache support, the context hash used to isolate cached responses between...
Moderate
Unreviewed
CVE-2026-59308
was published
Aug 21, 2026
HTTP.sys Information Disclosure Vulnerability
Moderate
Unreviewed
CVE-2023-21687
was published
Feb 14, 2023
Microsoft Office Information Disclosure Vulnerability
Moderate
Unreviewed
CVE-2023-21714
was published
Feb 14, 2023
Azure Active Directory Information Disclosure Vulnerability
Moderate
Unreviewed
CVE-2021-42306
was published
Nov 25, 2021
Azure RTOS Information Disclosure Vulnerability This CVE ID is unique from CVE-2021-26444, CVE...
Moderate
Unreviewed
CVE-2021-42301
was published
May 24, 2022
A vulnerability in Cisco Firepower Threat Defense (FTD) Software could allow an authenticated,...
Moderate
Unreviewed
CVE-2021-34761
was published
May 24, 2022
n8n's JavaScript task runner shared a single module cache across all users' Code-node executions....
Moderate
Unreviewed
CVE-2026-72764
was published
Aug 11, 2026
Electron: ProtocolResponse.url reuses the default session cache instead of the registering session
Moderate
CVE-2026-70606
was published
for
electron
(npm)
Aug 5, 2026
The import hook in CPython that handles legacy *.pyc files (SourcelessFileLoader) is incorrectly...
Moderate
Unreviewed
CVE-2026-2297
was published
Mar 5, 2026
ViewComponent: Reused Component Instances Retain Stale Render Context
Moderate
CVE-2026-54497
was published
for
view_component
(RubyGems)
Jul 15, 2026
open-feature-operator: Cross-namespace FeatureFlagSource and InProcessConfiguration resolution exposes spec contents on multi-tenant clusters
Moderate
CVE-2026-54495
was published
for
github.com/open-feature/open-feature-operator
(Go)
Jul 15, 2026
Several web interfaces in D-Link DIR-868LW 1.12b have no authentication requirements for access,...
Moderate
Unreviewed
CVE-2021-33259
was published
May 24, 2022
The PlexTrac platform prior to version 1.28.0 allows for username enumeration via HTTP response...
Moderate
Unreviewed
CVE-2022-37146
was published
Sep 9, 2022
Steeltoe's static JWKS cache shared across schemes and never invalidated
Moderate
CVE-2026-50202
was published
for
Steeltoe.Security.Authentication.CloudFoundryBase
(NuGet)
Jul 2, 2026
OpenClaw: Sandboxed session spawn could expose the real workspace path to child prompts
Moderate
GHSA-6c4r-g249-wv3c
was published
for
openclaw
(npm)
Jul 2, 2026
TYPO3 ke_search path traversal from arbitrary table configuration input
Moderate
CVE-2026-46723
was published
for
tpwd/ke_search
(Composer)
May 19, 2026
PraisonAI has Memory State Leakage and Path Traversal in MultiAgent Context Handling
Moderate
CVE-2026-56078
was published
for
praisonaiagents
(pip)
Apr 8, 2026
NodeVM observability builtins leak host process and HTTP request data
Moderate
CVE-2026-47141
was published
for
vm2
(npm)
May 29, 2026
OpenFGA has cache-key delimiter injection in shared-iterator and v2 iterator that caches enables intra-store authorization-decision poisoning
Moderate
CVE-2026-48096
was published
for
github.com/openfga/openfga
(Go)
Jun 11, 2026
Apache Airflow exposes SQL stack trace despite "api/expose_stack_traces" set to false
Moderate
CVE-2026-30912
was published
for
apache-airflow-core
(pip)
Apr 18, 2026
Apache Airflow has an authorization bypass in DagRun wait endpoint
Moderate
CVE-2026-34538
was published
for
apache-airflow
(pip)
Apr 9, 2026
ProTip!
Advisories are also available from the
GraphQL API